Re: [gentoo-dev] Current unavoidable use of xz utils in Gentoo

2024-04-01 Thread James Le Cuirot
On Mon, 2024-04-01 at 20:51 +0200, Kévin GASPARD DE RENEFORT wrote: > > Thanks for clarifying that, it wasn't clear to me when I read the > > earlier e-mail. > > > > Personally I think the long term solution is to identify critical code > > bases that have a low bus factor before the bad actors

Re: [gentoo-dev] Current unavoidable use of xz utils in Gentoo

2024-04-01 Thread Kévin GASPARD DE RENEFORT
Thanks for clarifying that, it wasn't clear to me when I read the earlier e-mail. Personally I think the long term solution is to identify critical code bases that have a low bus factor before the bad actors do and make a concentrated community effort to help audit and maintain these code bases.

Re: [gentoo-dev] Current unavoidable use of xz utils in Gentoo

2024-04-01 Thread orbea
On Mon, 1 Apr 2024 12:01:13 -0400 Kenton Groombridge wrote: > On 24/04/01 08:40AM, orbea wrote: > > On Mon, 1 Apr 2024 11:14:15 -0400 > > Kenton Groombridge wrote: > > > > > On 24/03/31 12:13PM, Eddie Chapman wrote: > > > > Eli Schwartz wrote: > > > > > On 3/29/24 11:07 PM, Eddie

Re: [gentoo-dev] Current unavoidable use of xz utils in Gentoo

2024-04-01 Thread Kenton Groombridge
On 24/04/01 08:40AM, orbea wrote: > On Mon, 1 Apr 2024 11:14:15 -0400 > Kenton Groombridge wrote: > > > On 24/03/31 12:13PM, Eddie Chapman wrote: > > > Eli Schwartz wrote: > > > > On 3/29/24 11:07 PM, Eddie Chapman wrote: > > > > > > > >> Given what we've learnt in the last 24hrs about xz

Re: [gentoo-dev] Current unavoidable use of xz utils in Gentoo

2024-04-01 Thread orbea
On Mon, 1 Apr 2024 11:14:15 -0400 Kenton Groombridge wrote: > On 24/03/31 12:13PM, Eddie Chapman wrote: > > Eli Schwartz wrote: > > > On 3/29/24 11:07 PM, Eddie Chapman wrote: > > > > > >> Given what we've learnt in the last 24hrs about xz utilities, > > >> you could forgive a paranoid

Re: [gentoo-dev] Current unavoidable use of xz utils in Gentoo

2024-04-01 Thread Kenton Groombridge
On 24/03/31 12:13PM, Eddie Chapman wrote: > Eli Schwartz wrote: > > On 3/29/24 11:07 PM, Eddie Chapman wrote: > > > >> Given what we've learnt in the last 24hrs about xz utilities, you could > >> forgive a paranoid person for seriously considering getting rid > >> entirely of them from their

Re: [gentoo-dev] Current unavoidable use of xz utils in Gentoo

2024-04-01 Thread Azamat Hackimov
сб, 30 мар. 2024 г. в 06:07, Eddie Chapman : > > Given what we've learnt in the last 24hrs about xz utilities, you could > forgive a paranoid person for seriously considering getting rid entirely > of them from their systems, especially since there are suitable > alternatives available. Some

Re: [gentoo-dev] Current unavoidable use of xz utils in Gentoo

2024-04-01 Thread Michał Górny
On Mon, 2024-04-01 at 08:57 +0100, Eddie Chapman wrote: > I stand by and reiterate my view that there is far too much of a cavalier > attitude towards the matter in general out there including here in Gentoo. > But not in particular here, it is everywhere where this is being discussed > at the

Re: [gentoo-dev] Current unavoidable use of xz utils in Gentoo

2024-04-01 Thread Eli Schwartz
On 4/1/24 3:57 AM, Eddie Chapman wrote: > No, I don't need to do that. I don't appreciate suggestions to "just calm > down", especially when I'm not being hysterical. Your comment to me just > reinforces what I mean when I say there is far too much of a cavalier > attitude. I think you're

Re: [gentoo-dev] Current unavoidable use of xz utils in Gentoo

2024-04-01 Thread Eddie Chapman
Matt Jolly wrote: > Hi Eddie, > > On 31/3/24 21:13, Eddie Chapman wrote: > >> At the moment there is far too much of >> a cavalier attitude about the whole thing being shown by too many, >> including here I'm sad to see. > > It's obvious that this is something that you are very worried about, but